WORKFLOW 02 / 4 REVIEW STAGES

Data inventory → processor register → retention schedule

Carry one confirmed processing activity through systems, instructed providers and event-based lifecycle decisions while keeping unknowns visible.

LOCAL TOOLS / HUMAN CONFIRMATION REQUIRED

Outcome to assemble

A reconciled inventory row, linked processor evidence and an owner-approved retention record with testable deletion tasks.

Reviewed
2026-08-26
Legal status
editorial analysis
Source/method records
act-2023rules-2025rules-2025-corrigendumdpdp-store-method-0.2
Changelog
0.5.0 — first public static working guide.
FICTIONAL PRACTICE SCENARIO

A fictional support process uses an inbox, case platform and hosting provider. The team knows the purpose and owner but must confirm region, provider access, backup treatment and the event that starts deletion.

STAGED HANDOFF

Follow the evidence, not a score.

WORKFLOW 0.5
  1. 01

    Confirm one processing activity

    Map the system, data categories, purpose, people group, source, recipients, owner, region and evidence using the inventory mapper.

    Handoff
    One reviewable inventory row with unknown values stated explicitly.
    Stop and review
    Do not scale to the whole organisation until the vocabulary and evidence pattern work for one process.
  2. 02

    Reconcile every instructed provider

    Use the processor register to compare the inventory claim with instructions, contract evidence, locations, access, safeguards, incident contact, deletion and exit facts.

    Handoff
    Provider rows linked back to the same system and purpose.
    Stop and review
    Escalate role ambiguity or missing evidence; the tool cannot classify the relationship.
  3. 03

    Translate purpose completion into an event

    Use the retention builder to name an observable completion event and separately document policy choice, holds, warnings, archive, backup and deletion evidence.

    Handoff
    A versioned retention record connected to the inventory owner and system mechanism.
    Stop and review
    Do not invent a duration. Applicable-law and business choices require authorised review.
  4. 04

    Run the cross-record consistency check

    Compare names, owners, purposes, locations, providers, lifecycle triggers and evidence links across all three exports.

    Handoff
    A short issue list for contradictory or missing facts and a controlled evidence pack after resolution.
    Stop and review
    A consistent set of documents can still be incomplete; ask system and provider owners to confirm the real flow.

Before the pack moves on

  • System, purpose and owner labels reconcile across the three records.
  • Every provider row connects to a confirmed inventory flow.
  • The retention event, backup treatment and deletion evidence are operationally testable.
  • Unknowns remain visible with owners instead of becoming guessed values.
WORKFLOW LIMIT

This workflow does not discover systems, read contracts, classify legal roles, prescribe retention periods or execute deletion.